CVE-2026-29784 Details
Description
Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /session/verify made it possible to use OTCs in login sessions different from the requesting session. In some scenarios this might have made it easier for phishers to take over a Ghost site. This issue has been patched in version 6.19.3.
A vulnerability exists in Ghost, a Node.js content management system, specifically in versions 5.101.6 prior to 6.19.2. The issue stems from incomplete Cross-Site Request Forgery (CSRF) protections around the '/session/verify' endpoint. This flaw allowed One-Time Codes (OTCs) to be used in login sessions that were different from the session making the request. Consequently, this vulnerability could have facilitated phishing attempts to take over a Ghost site.
Users can update to Ghost version 6.19.3, which addresses this vulnerability. For self-hosters using Docker, instructions for updating are available in the Ghost documentation. Those with a Ghost-CLI install can also find update guidance in the official Ghost documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ghost ghost | >= 5.101.6, < 6.19.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 9, 2026 | Initial Analysis | [email protected] |
| Mar 7, 2026 | New CVE Received | [email protected] |